IPMediumSignal 59/100
71.6.233.191
Location
Boston, Massachusetts
ASN
AS10439
Rapid7 Labs - Traffic originating from this network is expected and part of Project Sonar opendata.rapid7.com/about
First Seen
Sep 20, 2020
Last Seen
Jun 14, 2026
Found in 16 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
59%
Signal Score
59 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
United States
RegionBoston, Massachusetts
ASNAS10439
OrganizationRapid7 Labs - Traffic originating from this network is expected and part of Project Sonar opendata.rapid7.com/about
Feed Intelligence Summary
16 reports59% confidence
16
Source reports
59%
Confidence score
Category tags
abuseaccount compromiseactive scanactive scanningadbhoney honeypotapplication layer protocolattackaustraliaautomated-attackbad reputationbotnetbotnet activitybrute forcebrute force attackbrute force attackerbrute force attacksbrute force attemptsbrute-forcecanadacloud infrastructurecloud infrastructure attackcloud servicescommand and controlcommand injectioncommunication protocolconpot honeypotcowriecowrie honeypotcredential accesscredential stuffingcredential-bruteforcingdata exfiltrationdata store exposuredatabase attackddosddos attackdecoy systemdenial of servicedigital oceandionaeadionaea honeypotdionaea payloadsdistributed attacksdnsdns attackexploitexploitation activityexploited hostexternal scanfattfatt detectionsfraud voipftpftp brute forceftp brute-forcehackinghoneytrap eventshoneytrap honeypothttp brute forcehttp scannerics securityidentity & access exploitationinbound scanindicatorindicators of compromiseindustrial control systemsinformation gatheringinitial accessinjection activityintrusion detectioniociot securityiot/ics attackip-addressesipphoney honeypotipv4kfsensor honeypotlamplateral movementmailoney eventsmailoney honeypotmalicious activitymalicious softwaremalicious trafficmalwaremalware behaviourmalware capturemasscannetworknetwork attacksnetwork intrusion attemptsnetwork probingnetwork protocolnetwork reconnaissancenetwork scanningnetwork securitynetwork service scanningnetwork-reconnaissancenmapnorth americaoceaniaopportunistic-attackos credential dumpingp0fp0f signaturespassword attacksphishingphishing attackphishing trapping of deathportscanprocess injectionprotocol exploitationransomwarerapid7sonar-benignreconnaissanceremote accessremote servicesresearchedresource hijackingsansscams & fraudscannerscannersscanning activityscripting attackssecurity operationssensor-taggedsentrypeer botnetsentrypeer eventsservice enumerationservice scansftp attacksip brute forcesip vulnerability exploitationsmtpsmtp brute forcespamsshssh attackssh monitoringsuricata alertssynsystem discoveryt1018t1021t1021.001t1040t1041t1046t1055t1059t1059.007t1068t1071t1071.001t1076t1078t1087t1087.001t1087.002t1087.003t1110t1110.001t1110.002t1110.003t1110.004t1133t1189t1190t1203t1204.002t1486t1496t1499.001t1499.002t1499.003t1563t1565t1590t1592t1595t1595.001t1595.002t1595.003tannertanner eventstargeting databasetcp protocoltelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencetor nodetpotunauthorized access attemptunauthorized scanningunited statesusverified-benignvoipvoip attackvulnerability scanvultrweb application attackweb attackweb exploitationweb spamweb traffic
Activity Timeline
Jun 14Jun 14
Threat Activity Heatmap
· Peak: 2026-06-14LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
59
SIGNAL
Signal Score
59%
Confidence
16
Reports
First seenSep 20, 2020
Last seenJun 14, 2026
GeolocationUS
CountryUnited States
LocationBoston, Massachusetts
ASNAS10439
OrgRapid7 Labs - Traffic originating from this network is expected and part of Project Sonar opendata.rapid7.com/about
Coords42.3538, -71.0574
VirusTotal
Not checked
WHOIS
- description
- Observed on T-Pot within last 24h; sensors=p0f; threshold?1; private IPs excluded. geo=US; ports=3000 Location=Sydney, Australia.
- raw
- CariNet, Inc. CARINET-5 (NET-71-6-128-0-1) 71.6.128.0 - 71.6.255.255 Rapid7 Labs - Traffic originating from this network is expected and part of Rapid7 Labs Project Sonar opendata.rapid7.com/about NET-71-6-233-0-24 (NET-71-6-233-0-1) 71.6.233.0 - 71.6.233.255
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 5 years ago · Last seen 10 days ago
Appeared in 16 threat reports